| 2026 | AsiaCCS | StealthCup: Realistic, Multi-Stage, Evasion-Focused CTF for Benchmarking IDS. | Manuel Kern, Dominik Steffan, Felix Schuster, Florian Skopik, Max Landauer, David Allison, Simon Freudenthaler, Edgar R. Weippl |
| 2025 | CCS | Leaky Apps: Large-scale Analysis of Secrets Distributed in Android and iOS Apps. | David Schmidt, Sebastian Schrittwieser, Edgar R. Weippl |
| 2024 | Mobisys | Why E.T. Can't Phone Home: A Global View on IP-based Geoblocking at VoWiFi. | Gabriel K. Gegenhuber, Philipp . Frenzel, Edgar R. Weippl |
| 2024 | SECRYPT | Code Obfuscation Classification Using Singular Value Decomposition on Grayscale Image Representations. | Sebastian Raubitzek, Sebastian Schrittwieser, Caroline Lawitschka, Kevin Mallinger, Andreas Ekelhart, Edgar R. Weippl |
| 2024 | SECRYPT | Safe or Scam? An Empirical Simulation Study on Trust Indicators in Online Shopping. | Sebastian Schrittwieser, Andreas Ekelhart, Esther Seidl, Edgar R. Weippl |
| 2023 | ESORICS | Modeling Obfuscation Stealth Through Code Complexity. | Sebastian Schrittwieser, Elisabeth Wimmer, Kevin Mallinger, Patrick Kochberger, Caroline Lawitschka, Sebastian Raubitzek, Edgar R. Weippl |
| 2023 | SECRYPT | Large Language Models for Code Obfuscation Evaluation of the Obfuscation Capabilities of OpenAI's GPT-3.5 on C Source Code. | Patrick Kochberger, Maximilian Gramberger, Sebastian Schrittwieser, Caroline Lawitschka, Edgar R. Weippl |
| 2022 | ESORICS | Opportunistic Algorithmic Double-Spending: - How I Learned to Stop Worrying and Love the Fork. | Nicholas Stifter, Aljosha Judmayer, Philipp Schindler, Edgar R. Weippl |
| 2022 | FC | User-Perceived Privacy in Blockchain. | Simin Ghesmati, Walid Fdhila, Edgar R. Weippl |
| 2022 | FC | Estimating (Miner) Extractable Value is Hard, Let's Go Shopping! | Aljosha Judmayer, Nicholas Stifter, Philipp Schindler, Edgar R. Weippl |
| 2022 | GLOBECOM | Zero-Rating, One Big Mess: Analyzing Differential Pricing Practices of European MNOs. | Gabriel K. Gegenhuber, Wilfried Mayer, Edgar R. Weippl |
| 2022 | HCI | Mental Models of the Internet and Its Online Risks: Children and Their Parent(s). | Alexandra Mai, Leonard Guelmino, Katharina Pfeffer, Edgar R. Weippl, Katharina Krombholz |
| 2022 | HCI | Are HTTPS Configurations Still a Challenge?: Validating Theories of Administrators' Difficulties with TLS Configurations. | Alexandra Mai, Oliver Schedler, Edgar R. Weippl, Katharina Krombholz |
| 2022 | WWW | How much is the fork? Fast Probability and Profitability Calculation during Temporary Forks. | Aljosha Judmayer, Nicholas Stifter, Philipp Schindler, Edgar R. Weippl |
| 2022 | SAC | Strategic selection of data sources for cyber attack detection in enterprise networks: a survey and approach. | Manuel Kern, Florian Skopik, Max Landauer, Edgar R. Weippl |
| 2022 | SOUPS | Replication: Stories as Informal Lessons about Security. | Katharina Pfeffer, Alexandra Mai, Edgar R. Weippl, Emilee Rader, Katharina Krombholz |
| 2021 | BPM | Studying Bitcoin Privacy Attacks and Their Impact on Bitcoin-Based Identity Methods. | Simin Ghesmati, Walid Fdhila, Edgar R. Weippl |
| 2021 | CCS | Better Keep Cash in Your Boots - Hardware Wallets are the New Single Point of Failure. | Adrian Dabrowski, Katharina Pfeffer, Markus Reichel, Alexandra Mai, Edgar R. Weippl, Michael Franz |
| 2021 | FC | SoK: Algorithmic Incentive Manipulation Attacks on Permissionless PoW Cryptocurrencies. | Aljosha Judmayer, Nicholas Stifter, Alexei Zamyatin, Itay Tsabary, Ittay Eyal, Peter Gazi, Sarah Meiklejohn, Edgar R. Weippl |
| 2021 | FC | Pay to Win: Cheap, Cross-Chain Bribing Attacks on PoW Cryptocurrencies. | Aljosha Judmayer, Nicholas Stifter, Alexei Zamyatin, Itay Tsabary, Ittay Eyal, Peter Gazi, Sarah Meiklejohn, Edgar R. Weippl |
| 2021 | HCI | Unnecessary Input Heuristics and PayJoin Transactions. | Simin Ghesmati, Andreas Kern, Aljosha Judmayer, Nicholas Stifter, Edgar R. Weippl |
| 2021 | NDSS | RandRunner: Distributed Randomness from Trapdoor VDFs with Strong Uniqueness. | Philipp Schindler, Aljosha Judmayer, Markus Hittmeir, Nicholas Stifter, Edgar R. Weippl |
| 2020 | SP | HydRand: Efficient Continuous Distributed Randomness. | Philipp Schindler, Aljosha Judmayer, Nicholas Stifter, Edgar R. Weippl |
| 2020 | SEC | Actively Probing Routes for Tor AS-Level Adversaries with RIPE Atlas. | Wilfried Mayer, Georg Merzdovnik, Edgar R. Weippl |
| 2020 | SOUPS | User Mental Models of Cryptocurrency Systems - A Grounded Theory Approach. | Alexandra Mai, Katharina Pfeffer, Matthias Gusenbauer, Edgar R. Weippl, Katharina Krombholz |
| 2019 | ESORICS | Towards Data Anonymization in Data Mining via Meta-heuristic Approaches. | Fatemeh Amiri, Gerald Quirchmayr, Peter Kieseberg, Edgar R. Weippl, Alessio Bertone |
| 2019 | ETFA | Enhancing Cyber Situational Awareness for Cyber-Physical Systems through Digital Twins. | Matthias Eckhart, Andreas Ekelhart, Edgar R. Weippl |
| 2019 | ETFA | Avoiding Risky Designs When Using Blockchain Technologies in Cyber-Physical Systems. | Nicholas Stifter, Matthias Eckhart, Bernhard Brenner, Edgar R. Weippl |
| 2019 | FC | Echoes of the Past: Recovering Blockchain Metrics from Merged Mining. | Nicholas Stifter, Philipp Schindler, Aljosha Judmayer, Alexei Zamyatin, Andreas Kern, Edgar R. Weippl |
| 2019 | INDIN | A Versatile Security Layer for AutomationML. | Bernhard Brenner, Edgar R. Weippl, Andreas Ekelhart |
| 2019 | IECON | Security Related Technical Debt in the Cyber-Physical Production Systems Engineering Process. | Bernhard Brenner, Edgar R. Weippl, Andreas Ekelhart |
| 2019 | IECON | Security Development Lifecycle for Cyber-Physical Production Systems. | Matthias Eckhart, Andreas Ekelhart, Arndt Lder, Stefan Biffl, Edgar R. Weippl |
| 2019 | PAM | Measuring Cookies and Web Privacy in a Post-GDPR World. | Adrian Dabrowski, Georg Merzdovnik, Johanna Ullrich, Gerald Sendera, Edgar R. Weippl |
| 2018 | DBSEC | USBlock: Blocking USB-Based Keypress Injection Attacks. | Sebastian Neuner, Artemios G. Voyiatzis, Spiros Fotopoulos, Collin Mulliner, Edgar R. Weippl |
| 2018 | ESORICS | Pitchforks in Cryptocurrencies: - Enforcing Rule Changes Through Offensive Forking- and Consensus Techniques (Short Paper). | Aljosha Judmayer, Nicholas Stifter, Philipp Schindler, Edgar R. Weippl |
| 2018 | FC | A Wild Velvet Fork Appears! Inclusive Blockchain Protocol Changes in Practice - (Short Paper). | Alexei Zamyatin, Nicholas Stifter, Aljosha Judmayer, Philipp Schindler, Edgar R. Weippl, William J. Knottenbelt |
| 2018 | RAID | Proof-of-Blackouts? How Proof-of-Work Cryptocurrencies Could Affect Power Grids. | Johanna Ullrich, Nicholas Stifter, Aljosha Judmayer, Adrian Dabrowski, Edgar R. Weippl |
| 2017 | ACSAC | Grid Shock: Coordinated Load-Changing Attacks on Power Grids: The Non-Smart Power Grid is Vulnerable to Cyber Attacks as Well. | Adrian Dabrowski, Johanna Ullrich, Edgar R. Weippl |
| 2017 | ESORICS | Merged Mining: Curse or Cure? | Aljosha Judmayer, Alexei Zamyatin, Nicholas Stifter, Artemios G. Voyiatzis, Edgar R. Weippl |
| 2017 | RCIS | Research methods and examples of empirical research in information security. | Edgar R. Weippl |
| 2017 | SACMAT | Poster: Design of an Anomaly-based Threat Detection & Explication System. | Robert Luh, Sebastian Schrittwieser, Stefan Marschalek, Helge Janicke, Edgar R. Weippl |
| 2016 | CCS | Condensed Cryptographic Currencies Crash Course (C5). | Aljosha Judmayer, Edgar R. Weippl |
| 2016 | DBSEC | Whom You Gonna Trust? A Longitudinal Study on TLS Notary Services. | Georg Merzdovnik, Klaus Falb, Martin Schmiedecker, Artemios G. Voyiatzis, Edgar R. Weippl |
| 2016 | ESORICS | The Beauty or The Beast? Attacking Rate Limits of the Xen Hypervisor. | Johanna Ullrich, Edgar R. Weippl |
| 2016 | FC | The Other Side of the Coin: User Experiences with Bitcoin Security and Privacy. | Katharina Krombholz, Aljosha Judmayer, Matthias Gusenbauer, Edgar R. Weippl |
| 2016 | ICISSP | Ethics in Security Research. | Edgar R. Weippl |
| 2016 | ICISSP | Empirical Research and Research Ethics in Information Security. | Edgar R. Weippl, Sebastian Schrittwieser, Sylvi Rennert |
| 2016 | Networking | Pin it! Improving Android network security at runtime. | Damjan Buhov, Markus Huber, Georg Merzdovnik, Edgar R. Weippl |
| 2016 | RAID | The Messenger Shoots Back: Network Operator Based IMSI Catcher Detection. | Adrian Dabrowski, Georg Petzl, Edgar R. Weippl |
| 2016 | WWW | Cryptographic Currencies Crash Course (C4): Tutorial. | Aljosha Judmayer, Edgar R. Weippl |
| 2016 | SP | Browser History Stealing with Captive Wi-Fi Portals. | Adrian Dabrowski, Georg Merzdovnik, Nikolaus Kommenda, Edgar R. Weippl |
| 2015 | FC | Ok Glass, Leave Me Alone: Towards a Systematization of Privacy Enhancing Technologies for Wearable Computing. | Katharina Krombholz, Adrian Dabrowski, Matthew Smith, Edgar R. Weippl |
| 2015 | IIWAS | WordPress security: an analysis based on publicly available exploits. | Hannes Trunde, Edgar R. Weippl |
| 2015 | ICST | Security tests for mobile applications - Why using TLS/SSL is not enough. | Peter Kieseberg, Peter Frhwirt, Sebastian Schrittwieser, Edgar R. Weippl |
| 2015 | RAID | Privacy is Not an Option: Attacking the IPv6 Privacy Extension. | Johanna Ullrich, Edgar R. Weippl |
| 2015 | SP | Error-Correcting Codes as Source for Decoding Ambiguity. | Adrian Dabrowski, Isao Echizen, Edgar R. Weippl |
| 2014 | ACSAC | IMSI-catch me if you can: IMSI-catcher-catchers. | Adrian Dabrowski, Nicola Pianta, Thomas Klepp, Martin Mulazzani, Edgar R. Weippl |
| 2014 | CCS | QR Inception: Barcode-in-Barcode Attacks. | Adrian Dabrowski, Katharina Krombholz, Johanna Ullrich, Edgar R. Weippl |
| 2014 | CloudCom | A Multi-layer and MultiTenant Cloud Assurance Evaluation Methodology. | Aleksandar Hudic, Markus Tauber, Thomas Lornser, Maria Krotsiani, George Spanoudakis, Andreas Mauthe, Edgar R. Weippl |
| 2014 | HCI | E-voting Authentication with QR-codes. | Stefanie Falkner, Peter Kieseberg, Dimitris E. Simos, Christina Traxler, Edgar R. Weippl |
| 2014 | HCI | QR Code Security: A Survey of Attacks and Challenges for Usable Security. | Katharina Krombholz, Peter Frhwirt, Peter Kieseberg, Ioannis Kapsalis, Markus Huber, Edgar R. Weippl |
| 2014 | IIWAS | A Decision Framework Model for Migration into Cloud: Business, Application, Security and Privacy Perspectives. | Shareeful Islam, Edgar R. Weippl, Katharina Krombholz |
| 2014 | IIWAS | What's new with WhatsApp & Co.? Revisiting the Security of Smartphone Messaging Applications. | Robin Mueller, Sebastian Schrittwieser, Peter Frhwirt, Peter Kieseberg, Edgar R. Weippl |
| 2014 | IIWAS | Empirical Research in Information Security. | Edgar R. Weippl |
| 2014 | SECRYPT | Advanced Persistent Threats & Social Engineering. | Edgar R. Weippl |
| 2014 | SIN | Plugin in the Middle - Minimising Security Risks in Mobile Middleware Implementations. | Peter Aufner, Georg Merzdovnik, Markus Huber, Edgar R. Weippl |
| 2014 | SIN | Towards Practical Methods to Protect the Privacy of Location Information with Mobile Devices. | Christoph Hochreiner, Markus Huber, Georg Merzdovnik, Edgar R. Weippl |
| 2013 | CCS | Cloudoscopy: services discovery and topology mapping. | Amir Herzberg, Haya Schulmann, Johanna Ullrich, Edgar R. Weippl |
| 2013 | CCS | Covert computation: hiding code in code for obfuscation purposes. | Sebastian Schrittwieser, Stefan Katzenbeisser, Peter Kieseberg, Markus Huber, Manuel Leithner, Martin Mulazzani, Edgar R. Weippl |
| 2013 | SMC | Framework Based on Privacy Policy Hiding for Preventing Unauthorized Face Image Processing. | Adrian Dabrowski, Edgar R. Weippl, Isao Echizen |
| 2013 | SEC | Towards Security-Enhanced and Privacy-Preserving Mashup Compositions. | Heidelinde Hobel, Johannes Heurix, Amin Anjomshoaa, Edgar R. Weippl |
| 2013 | SIN | Social engineering attacks on the knowledge worker. | Katharina Krombholz, Heidelinde Hobel, Markus Huber, Edgar R. Weippl |
| 2012 | IIWAS | Digital forensics for enterprise rights management systems. | Sebastian Schrittwieser, Peter Kieseberg, Edgar R. Weippl |
| 2012 | IIWAS | Is security an afterthought when designing apps? | Edgar R. Weippl |
| 2012 | IIWAS | INMOTOS: extending the ROPE-methodology. | Lorenz Zechner, Peter Kieseberg, Edgar R. Weippl |
| 2012 | NDSS | Guess Who's Texting You? Evaluating the Security of Smartphone Messaging Applications. | Sebastian Schrittwieser, Peter Frhwirt, Peter Kieseberg, Manuel Leithner, Martin Mulazzani, Markus Huber, Edgar R. Weippl |
| 2011 | ACSAC | Social snapshots: digital forensics for online social networks. | Markus Huber, Martin Mulazzani, Manuel Leithner, Sebastian Schrittwieser, Gilbert Wondracek, Edgar R. Weippl |
| 2011 | IIWAS | Using the structure of B+-trees for enhancing logging mechanisms of databases. | Peter Kieseberg, Sebastian Schrittwieser, Lorcan Morgan, Martin Mulazzani, Markus Huber, Edgar R. Weippl |
| 2011 | IWDW | An Algorithm for k-Anonymity-Based Fingerprinting. | Sebastian Schrittwieser, Peter Kieseberg, Isao Echizen, Sven Wohlgemuth, Noboru Sonehara, Edgar R. Weippl |
| 2011 | SERVICES | IT Governance, Risk & Compliance (GRC) Status Quo and Integration: An Explorative Industry Case Study. | Nicolas Racz, Edgar R. Weippl, Riccardo Bonazzi |
| 2010 | ACIIDS | Context Oriented Analysis of Web 2.0 Social Network Contents - MindMeister Use-Case. | Amin Anjomshoaa, Khue Vo Sao, A Min Tjoa, Edgar R. Weippl, Michael Hollauf |
| 2010 | AINA | InnoDB Database Forensics. | Peter Frhwirt, Markus Huber, Martin Mulazzani, Edgar R. Weippl |
| 2010 | CCS | Cheap and automated socio-technical attacks based on social networking sites. | Markus Huber, Martin Mulazzani, Sebastian Schrittwieser, Edgar R. Weippl |
| 2010 | CCS | Exploiting social networking sites for spam. | Markus Huber, Martin Mulazzani, Edgar R. Weippl, Gerhard Kitzler, Sigrun Goluch |
| 2010 | ESEM | An event-based empirical process analysis framework. | Wikan Danar Sunindyo, Stefan Biffl, Richard Mordinyi, Thomas Moser, Alexander Schatten, Mohammed Tabatabai Irani, Dindin Wahyudin, Edgar R. Weippl, Dietmar Winkler |
| 2010 | GI | Questioning the Need for Separate IT Risk Management Frameworks. | Nicolas Racz, Edgar R. Weippl, Andreas Seufert |
| 2010 | ICALT | Implementation of Affective States and Learning Styles Tactics in Web-Based Learning Management Systems. | Farman Ali Khan, Sabine Graf, Edgar R. Weippl, A Min Tjoa |
| 2010 | KSEM | A SOM-Based Technique for a User-Centric Content Extraction and Classification of Web 2.0 with a Special Consideration of Security Aspects. | Amirreza Tahamtan, Amin Anjomshoaa, Edgar R. Weippl, A Min Tjoa |
| 2010 | MOMM | QR code security. | Peter Kieseberg, Manuel Leithner, Martin Mulazzani, Lindsay Munroe, Sebastian Schrittwieser, Mayank Sinha, Edgar R. Weippl |
| 2010 | SEC | Who on Earth Is "Mr. Cypher": Automated Friend Injection Attacks on Social Networking Sites. | Markus Huber, Martin Mulazzani, Edgar R. Weippl |
| 2009 | IIWAS | Can end-to-end verifiable e-voting be explained easily? | Peter Kalchgruber, Edgar R. Weippl |
| 2009 | IIWAS | An approach for identifying affective states through behavioral patterns in web-based learning management systems. | Farman Ali Khan, Sabine Graf, Edgar R. Weippl, A Min Tjoa |
| 2009 | KSEM | Blending the Sketched Use Case Scenario with License Agreements Using Semantics. | Muhammad Asfand-e-yar, Amin Anjomshoaa, Edgar R. Weippl, A Min Tjoa |
| 2008 | AINA | Fortification of IT Security by Automatic Security Advisory Processing. | Stefan Fenz, Andreas Ekelhart, Edgar R. Weippl |
| 2007 | IIWAS | Security aspects in Semantic Web Services Filtering. | Witold Abramowicz, Andreas Ekelhart, Stefan Fenz, Monika Kaczmarek, A Min Tjoa, Edgar R. Weippl, Dominik Zyskowski |
| 2007 | IIWAS | A Comparative Literature Review on RFID Security and Privacy. | Bernhard Riedl, Gernot Goluch, Stefan Pchlinger, Edgar R. Weippl |
| 2007 | IRI | Question Driven Semantics Interpretation for Collaborative Knowledge Engineering and Ontology Reuse. | Khalid Latif, Edgar R. Weippl, A Min Tjoa |
| 2007 | PRDC | Information Security Fortification by Ontological Mapping of the ISO/IEC 27001 Standard. | Stefan Fenz, Gernot Goluch, Andreas Ekelhart, Bernhard Riedl, Edgar R. Weippl |
| 2007 | SEC | Ontological Mapping of Common Criteria's Security Assurance Requirements. | Andreas Ekelhart, Stefan Fenz, Gernot Goluch, Edgar R. Weippl |
| 2006 | ICISS | Security Ontology: Simulating Threats to Corporate Assets. | Andreas Ekelhart, Stefan Fenz, Markus D. Klemen, Edgar R. Weippl |
| 2006 | IIWAS | Do we Really Need Access Control? | Edgar R. Weippl |
| 2006 | PRDC | Ontology based IT-security planning. | Stefan Fenz, Edgar R. Weippl |
| 2005 | AICCSA | Privacy in E-learning: How to implement anonymity. | Edgar R. Weippl, A Min Tjoa |
| 2005 | DEXA | Semantic Storage: A Report on Performance and Flexibility. | Edgar R. Weippl, Markus D. Klemen, Manfred Linnert, Stefan Fenz, Gernot Goluch, A Min Tjoa |
| 2004 | IIWAS | Security in E-Learning. | Edgar R. Weippl |
| 2004 | ICWE | From Maintenance to Evolutionary Development of Web Applications: A Pragmatic Approach. | Rudolf Ramler, Klaus Wolfmaier, Edgar R. Weippl |
| 2003 | IIWAS | Can P2P Deliver What Web Repositories Promised: Global Sharing of E-Learning Content? | Reinhard Kronsteiner, Edgar R. Weippl, Ismail Khalil Ibrahim, Gabriele Kotsis |
| 2003 | IIWAS | Security in E-Learning. | Edgar R. Weippl |
| 2002 | ACSAC | Reusable Components for Developing Security-Aware Application. | Stefan Probst, Wolfgang Emayr, Edgar R. Weippl |
| 2002 | DEXA | CoSMo: An Approach Towards Conceptual Security Modeling. | Christine Artelsmair, Wolfgang Emayr, Peter Lang, Roland R. Wagner, Edgar R. Weippl |
| 2000 | DEXA | Fine Grained Replication in Distributed Databases: A Taxonomy and Practical Considerations. | Edgar R. Weippl, Wolfgang Emayr |
| 2000 | EJC | Knowledge Landscapes: A VR Interface for Web-Based Training Knowledge Bases. | Edgar R. Weippl, Hans Lohninger |
| 2000 | SEC | Identity Mapping: An Approach to Unravel Enterprise Security Management Policies. | Wolfgang Emayr, Edgar R. Weippl |